-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| io.jenkins.plugins:github-coverage-reporter | maven | <= 1.10 |
The vulnerability stems from unencrypted storage of credentials in XML configuration files. Jenkins plugin configuration typically uses Descriptor.configure() methods for global settings. The PluginConfiguration class would handle credential storage, and the absence of encryption in the configure() method (which persists settings) or associated getters/setters directly enables plaintext storage. While exact implementation details aren't visible, this pattern matches Jenkins plugin architecture and the described vulnerability mechanism.
Ongoing coverage of React2Shell